Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-87902 Vulnerabilities

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Attackers are actively exploiting WordPress CVE-2026-87902, a critical CVSS 9.2 flaw that enables unauthenticated local PHP file inclusion and conditional remote code execution.

Threat actors have begun actively exploiting CVE-2026-87902, a critical vulnerability in WordPress Core, only hours after details and security updates became publicly available.

The vulnerability carries a CVSS score of 9.2 and allows an unauthenticated attacker to include arbitrary local PHP files outside the active theme directories. Under specific server and theme conditions, the flaw can be escalated to remote code execution (RCE).

CVE-2026-87902 at a Glance

Detail Information
CVE CVE-2026-87902
Product WordPress Core
Severity Critical – CVSS 9.2
Authentication Not required
Primary Issue Path traversal / Local PHP file inclusion
Potential Impact Remote Code Execution
Affected WordPress 4.7.0 through 7.1.1
Exploitation Active

WordPress fixed the vulnerability in 7.1.2, with security fixes also backported to supported older branches.

How the Attack Works

The vulnerability exists in WordPress's get_page_template() page-template resolution process. A specially crafted request can cause WordPress to load a readable PHP file located outside the expected theme directory.

Successful RCE requires additional conditions, including:

  • The active parent or child theme has a top-level directory beginning with page-, such as page-templates.
  • A suitable local PHP file is present and readable by the web-server account.

Attackers have already been observed targeting:

/usr/local/lib/php/pearcmd.php

By abusing pearcmd.php, attackers can write malicious PHP files to disk and potentially execute attacker-controlled code.

The attack path can be summarized as:

Malicious Request → Path Traversal → Local PHP Inclusion → pearcmd.php Abuse → PHP File Write → Potential RCE

Exploitation Began Within Hours

Patchstack initially detected probing on September 22, 2026, less than five hours after WordPress 7.1.2 was released. Early activity focused on including harmless WordPress files to determine whether websites were vulnerable.

Attackers subsequently moved to active exploitation using pearcmd.php to write PHP files. Reported filenames include:

  • wp-pear-rce-flag.php
  • poc87902.php
  • luci_<random>.php
  • zeta_<random>.php

Previdian also recorded exploitation attempts against its honeypots beginning September 23.

On September 25, CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that the vulnerability is being exploited in the wild.

What WordPress Administrators Should Do

Administrators should immediately upgrade to a patched WordPress release, including:

  • 7.1.2 or later
  • 7.0.6 or later
  • 6.9.9 or later
  • 6.8.10 or later
  • Appropriate security backport for older supported branches

Because exploitation began shortly after disclosure, administrators should not rely only on patching. Previously exposed systems should also be checked for unexpected PHP files, modifications under /tmp and /var/tmp, suspicious page-template requests, unknown administrator accounts, web shells and unusual outbound connections.

Security Takeaway

CVE-2026-87902 demonstrates how quickly attackers can weaponize newly disclosed vulnerabilities.

Disclosure → Vulnerability Probing → Local File Inclusion → PHP File Write → Potential Server Compromise

Although remote code execution requires specific environmental conditions, active exploitation has already been confirmed. WordPress administrators should therefore prioritize patching and investigate systems that were exposed before the security update was installed.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.